Security Center
Public threat model
What FC1 Network E2EE is designed to protect against — and important limits. This is not an exploit guide.
Design goalsExplicit non-goalsEndpoint reality
Designed protections
- Network private message bodies are not stored as plaintext for server-side reading.
- Lost-server scenarios should not yield readable DM bodies without device/recovery secrets.
- Users can revoke devices and enroll recovery options to reduce lockout and takeover risk.
What this does not promise
- Protection if an attacker already controls your unlocked phone or malware-infected browser.
- Hiding metadata that operations require (approximate timing, routing, abuse signals).
- “Unhackable,” “military-grade,” or “most secure network” marketing claims.
- E2EE for every FC1 surface (support, payments, listings, admin tools).
Report vulnerabilities
Email security@fceone.com. See security.txt. We do not publish a public bug bounty program on this page unless one is actually running.
Keep recovery options healthy
Passkeys, recovery codes, and device hygiene matter more than slogans.